Possible intrusion begins
The actual entry date and dwell time are unknown. Detection time is not the same as compromise time.
Medtech cyber incident · evidence-based visual brief
A cyber incident detected on August 25, 2026 caused a global network outage that disrupted manufacturing, order processing, shipping and some new cardiac remote-monitoring activations. The company activated incident response and brought in outside experts, but has not publicly identified the actor, entry path or dwell time.
Public-information cutoff · August 29, 2026 · UTCNo public source reviewed identifies the actor, initial-access method, ransomware family, ransom demand or confirmed data theft.
The actual entry date and dwell time are unknown. Detection time is not the same as compromise time.
Boston Scientific detects affected IT systems, activates response protocols and starts containment with third-party specialists.
SEC Form 8-K filed. Company confirms global disruption, manufacturing and order/shipping impact; EDI orders are queued.
Core-business-system recovery is progressing, but no full-restoration date is given. Product-risk findings are updated.
Boston Scientific says it “identified” the incident; the actual telemetry or alert source has not been disclosed.
Public disclosure is not evidence that law enforcement was—or was not—contacted privately.
Actions confirmed by Boston Scientific—not inferred.
Recommendations—not claims about Boston Scientific's pre-incident controls.
Evidence rule: “unknown” means not established in the cited public record as of the cutoff—not proof that the event or action did not occur.